thinnawarth mathuros

thinnawarth mathuros is a security researcher credited with 6 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #696 of 3,515 contributors. Their disclosures were published between 2025 and 2026. The most productive year was 2026, with 3 findings.

Their research concentrates on Missing Authorization, which accounts for 3 of their findings (50%). Other recurring categories include Cross-Site Request Forgery (CSRF), Exposure Of Sensitive Information To An Unauthorized Actor. The average CVSS score across these disclosures is 5.2, peaking at 6.5.

The most affected software includes Events Manager (2), Blocks for ACF Fields (1), Blog2Social (1), across 5 distinct plugins, themes and core versions in total.

All 6 disclosed issues have since received a vendor fix.

20252026
Critical
High
Medium
Low

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C